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ETSI/TC LI presentations 

□ General Overview on the Work in ETSI/TC LI and 
Details on Lawful Interception Standardization 

> Peter van der Arend, Chairman ETSI/TC LI 

□ Security Framework for Lawful Interception and Retained Data 

> Vassilis Stathopoulosv, Helenic Authority for Communications Privacy 

□ Interception Domain Architecture for CS and IP Networks 

> Stefan Bjornson, Cecratech and 1st Vice Chairman ETSI/TC LI 

□ IP Interception: VoIP, e-mail, WLAN... 

> Mark Lastdrager, CEO, Pine Digital Security 

□ Requirements for Handling of Retained Data 

> Koen Jaspers, PIDS, Ministry of Justice 

□ Handover Interface for Retained Data 

> Mark Shepherd, NTAC Consultant of Security, Detica 
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Handover Interfaces for transport of 
Lawful Interception and Retained Data 
are standardised in Europe by ETSI 

European 

elecommunications 

Standards 

nstitute 
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Intro on ETSI 

□ A European standards organization, created in 1988, 
active in all areas of telecommunications 

> including radio communications, broadcasting and 
Information Technology 

□ Supporting EU and EFTA regulation and initiatives 

□ Favours international collaboration 

□ A not-for-profit organization 

□ Members: Administrations, Administration Bodies and NSOs 
Network Operators, Service Providers, Manufacturers, Users 

□ Creates different deliverables to meet market needs 

□ All publications freely available! Downloadable from ETSI Website 

h ttp ://pda. etsi. org/pda/queryform.asp 

h ttp :// portal, etsi. org 
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Global Standards Collaboration 

Interregional collaboration on selected 
standardization subjects between partners: 



'ccsa 

(China) 



isacc 

cccnt 
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(Japan) 
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Partnership Project 

3 rd Generation Partnership Project 

specifying a W-CDMA system based on 
an evolution of the GSM core network, a 
member of the ITU’s IMT-2000 family 

A GLOBAL INITIATIVI 

http ://www. 3gpp. org 




Organizational Partners: 

ETSI (Europe) CCSA (China) ARIB (Japan) 
ATIS (USA) TTA (Korea) TTC (Japan) 
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Status of ETSI Lawful Interception Standards 

and 

Introduction on 

Lawful Interception standardisation 
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Why Lawful Interception implementation in EU 

17th January 1995: EU Council of Ministers 
adopted resolution COM 96/C329/01 on Lawful Interception 




The providers of public telecommunications networks and services 
are legally required to make available to the authorities the 
information necessary to enable them to investigate 



telecommunications 
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Main body in ETSI for 

Lawful Interception Standards development 

and coordination is 

ETSI/TC LI 
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Why standardisation of LI handling 

□ Easier to define own LI mechanism 

> Guidance is given for network architecture 

> No need to define/invent complete own LI system 

> National options are possible 

□ “Cheaper” LI products 

> Manufacturers need to develop one basic product 

> National options are additional 

□ Intercepted result is meeting international requirements by 
Law Enforcement Agencies 

□ LI Standards in ETSI/TC LI are actively developed in good 
harmonization and are approved by all involved parties 
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History of ETSI/TC LI 



□ ETSI/Technical Committee Security (TC SEC) 

> Working Group Lawful Interception (SEC-WGLI) (1997) 

> TR 102 053 vl. 1. 1 ES 201 158 vl.2. 1 



□ ETSI/Technical Committee Lawful Interception (TC LI) 



> 

> 

> 

> 

> 

> 

> 

> 



Established as stand-alone TC in October 2002 



TR 101 943 V2.2.1 
TR 102 528 vl.1.1 
TS 101 331 vl.2.1 
TS 102232-1 V2.3.1 
TS 102232-4 v2.1.1 
TS 102232-7 V2.1.1 
TS 102 656 vl. 1.2 



TR 102 503 vl.4.1 

TS 101 671 V3.3.1 
TS 102 232-2 V2.3.1 
TS 102 232-5 V2.3.1 



TR 102 519 vl.1.1 

ES201 671 V3.1.1 
TS 102232-3 v2. 1.1 
TS 102232-6 V2.2.1 
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How ETSI/TC LI operates 



□ Meetings 

> Three plenary meetings a year are organised 
(35-80 participants) 

> In between if necessary Rapporteur’s meetings can be organised on a 
specific issue 

□ The meetings can be attended by ETSI members 

> Non-ETSI members can participate by invitation of the chairman 

□ Dedicated TC LI E-mail server and FTP server 

> Open to all ETSII (full and associated) members 

□ Producing reports and specifications on 
Lawful Interception and Retained Data 

□ Promoting globally ETSI Lawful Interception standards amongst 
operators and national bodies 
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Participation in ETSI/TC LI 



□ Law Enforcement Agencies / Governments organisations / 
Research organisations 



> All, CA, USA, KR 

□ Operators 

> KPN (NL), DT (DE), BT (UK), TeliaSonera (S), Inmarsat, Telenor (NO) 
UPC, Telstra, Telecom Italia, T-Mobile (DE), Vodafone, Wind, TDC (DK) 

□ Manufacturers (switch / mediation / LEA equipment) 

> Nokia Siemens Networks, Ericsson, Cisco, Alcatel-Lucent, Nortel 
Pine Digital Security, Aqsacom, ETI, VeriSign, GTEN, AREA, 

Verint, Detica, Thales, NICE Systems, Utimaco Safeware, Iskratel 
ATIS Systems, SS8, Spectronic, Group 2000, ZTE, HP, IPS 



> NL, UK, DE, AS, S, GR, ES, FR, RU, FIN, IT, NO, CY, HU, UA 



Manufacturers may be active in all areas 
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: jj LEA requirements (step 1) 

□ ETSI TS 101 331 

Requirements of Law Enforcement Agencies 

> Provides guidance in the area of co-operation by network 
operators/service providers with the lawful interception of 
telecommunications 

> Provides a set of requirements relating to handover interfaces for the 
interception 
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□ Intercept Related Information (IRI) 

> Collection of information or data associated with telecommunication 
services involving the target identity: 

• communication associated information or data 
(including unsuccessful communication attempts) 

• service associated information or data 

(e.g. service profile management by subscriber) 

• location information 



□ Content of Communication (CC) 

> information exchanged between two or more users of a 
telecommunications service 
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LI Handover Interface (step 3) 



□ ETSI TS 101 671 



(ETSI ES 201 671) 



Handover Interface for the Lawful Interception of 
Telecommunications Traffic 

> Generic flow of information and procedures and information 
elements, applicable to any future telecommunication network or 
service 

> Circuit switched and packet data 

> Covered technologies: 

PSTN, ISDN, GSM, UMTS (CS), GPRS, TETRA 
wireline NGN (including PSTN/ISDN emulation) 
wireline IMS PSTN simulation 

□ ETSI TR 102 053 

Notes on ISDN LI functionalities 

> Implementation advice of TS 101 671 for operators 
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□ HI1 : for Administrative Information 

> Request for lawful interception: 

target identity, LIID, start/duration, BRI or IRI+CC, 
IR1 delivery address, CC delivery address, ... 

> Management information 



□ HI2: for delivery of Intercept Related Information 

> All data related to establish the telecommunication service and to 
control its progress 

> Correlation information 



□ HI3: for delivery of Content of Communication 

> Transparent en-clair copy of the communication 

> Correlation information 
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Handover Interface Concept (tsioi 67 i> 

NWO/AP/SvP’s domain LEA 

domain 



Network 

Internal 

Functions 




NWO/AP,SvP’s 
ad ministration 
function 



HI1 



IRI mediation 
function 



CC mediation 
function 



UF 



HI2 



HI3 



mi 



LEMF 

LI handover interface HI 



II F : internal interception function 
INI: internal network interface 



HI1: administrative information 
HI2: intercept related information 
HI3: content of communication 
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□ IRI data is defined according ASN.1 description 

> STU-T Recommendation X.680 (Abstract Syntax Notation One) 



□ IRI Communication Associated Information 

> IRI-Begin 

• At first event of the communication attempt 

> IRI Continue 

• Any time during the communication (attempt) 

> IRI-End 

• At the end of the communication (attempt) 

□ IRI Service Associated Information 

> IRI-Report 

• For any non-communication related events 
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□ LI related identities 

> LIID, target, network operator, network element, call ID, ... 

□ Timestamp 

□ Intercepted call direction (to /from target) 

□ Intercepted call state (in progress, connected) 

□ Address: Calling party / Called party / Forwarded-to-party / .. 

> E.164, TEI, [MSI, IMEI, MSISDN, SIP URI, ... 

□ Ringing tone duration / conversation duration 

□ Type of intercept: 

> PSTN, ISDN, GSM (CS), TETRA, GPRS (PD), UMTS (CS) 

□ Supplementary service information 

□ Location information 

□ National parameters 

□ IRI record type (Begin, Continue, End, Report) 

□ .... 
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Interception network 
ISDN/PSTN Services 
step-by-step 



I/O 



BNI1 



Data 



HP Switching functions 
Call Content 



INI 



1 1 F 



IND 



IRI: Intercept Related Information 
CC Content of Communication 
INI: Internal Network Interface 
I IF: Internal Intercepting Function 
Al: Administrative Interface 



Management 
System 



Administration 

Function 1 



Mediation 
Function 2 




Mediation 
Function 3 




ISDI 



Mediator 



arrant 




Authorisation 
Authority / 
Law 
Enforcement 
Agency 



Law 

Enforcement 

Monitoring 

Facility 



HI2 

(IRI) 



HI 

(TS 10 



HI3 

(CC) 



671) 

HI: Handover Interface 
HI1 : Administration 
HI2: Intercept Related Information 
HI3: Content of Communication 
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Activities in ETSIVTC LI 

on 

Retained Data Handover Interface 
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Why study on Retained Data in EU 

15th of March 2006: the European Parliament 
and the Council of the European Union adopted 
Directive 2006/24/EC on Data Retention 




Data generated or processed in connection with 



publicly available electronic communications services 



the provision of 



or of 

public communications networks 
need to be retained 
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> guidance and requirements for the delivery and associated issues of 
retained data of telecommunications and subscribers 

> set of requirements relating to handover interfaces for retained data 

> requirements to support the implementation of Directive 2006/24/EC 



□ ETSI DTS/LI-00033 (will become TS 102 657) 

Handover interface for the request and delivery of Retained Data 

> handover requirements and handover specification for the data that 
is identified in EU Directive 2006/24/EC on Retained Data and in 
national legislations as defined in TS 102 656 

> considers both the requesting of retained data and the delivery of the 
results 

> defines an electronic interface 
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More details on ETSI/TC LI can be found on: 

http://portal.etsi.org/li/Summary.asp 

Chairman TC LI: Peter@lawfulinterception.com 

Peter @DataRetention.eu 
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